Impact
The vulnerability occurs when the ALSA bcd2000 USB driver frees USB Request Blocks (URBs) but does not clear the pointers. Subsequent operations on an open rawmidi stream can access these dangling pointers, writing to memory that has already been freed. This results in a use‑after‑free condition that corrupts kernel memory, potentially leading to a denial of service or, if an attacker can influence the data written to the URB, arbitrary code execution. No exploitation has been reported, but the memory corruption risk is real and could be leveraged by a privileged attacker.
Affected Systems
All Linux kernel releases that include the ALSA bcd2000 driver prior to the fix are affected. The issue targets the ALSA subsystem in the Linux kernel vendor, specifically the snd_bcd2000 module that manages bcd2000 USB audio devices. Systems that use rawmidi streams exposed by this driver are at risk.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity. The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low current exploitation probability. The likely attack vector is local: an attacker must be able to trigger a USB disconnect while a rawmidi stream remains open, which requires either physical or remote control of the USB device. The attack relies on a kernel use‑after‑free and, while not yet exploited in the wild, could lead to remote or local privilege escalation if an attacker controls the data sent to the freed URB.
OpenCVE Enrichment
Debian DSA